Getting Data In

Splunk For IIS?

khskinsfan
Engager

Is there a Splunk for IIS that can be used on version 4.x?

Thanks.

Tags (2)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

You should just be able to run a splunk instance on IIS and set up a data input to monitor the directory locally. There is an IIS sourcetype natively built into the product. A good place to start would be here:

http://www.splunk.com/base/Documentation/4.1.6/admin/WhatSplunkCanMonitor

View solution in original post

demodav
Path Finder

Link is no longer available

0 Karma

khskinsfan
Engager

I am looking for mostly the reporting aspect to produce meaningful reports for customer. Like request per month. Request per Client IP. User Agent reports, etc... At the moment I am not profiecient in writing the queries required to produce such charts in splunk. But working on it.

I have splunk looking at offline iis logs at the moment, nothing live.

0 Karma

southeringtonp
Motivator

Arguably a "web analytics" app would be better -- there's probably not that much of interest that specific to IIS over any other web server. I have some very preliminary stuff, and probably so do a lot of other people. But nothing usable enough to share yet.

araitz
Splunk Employee
Splunk Employee

There is definitely a need for an IIS app, or at least an add-on.

southeringtonp
Motivator

What are you looking for in the app - just parsing and field extractions, or more complete logic?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

You should just be able to run a splunk instance on IIS and set up a data input to monitor the directory locally. There is an IIS sourcetype natively built into the product. A good place to start would be here:

http://www.splunk.com/base/Documentation/4.1.6/admin/WhatSplunkCanMonitor

eantonio
Path Finder

I would like to monitor IIS logs on my remote Web Servers. How to I do that?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...